Zenity Labs

Research, tools, and talks about building and breaking AI Agents

Connect

Hero image
Sure, Let AI Browse the Internet—What Could Possibly Go Wrong?

Sure, Let AI Browse the Internet—What Could Possibly Go Wrong?

Internet browsing for AI agents leads to 0click compromise but these mitigations can help

Security Research
TTPs.ai for GenAI-Targeted Attacks

TTPs.ai for GenAI-Targeted Attacks

Guiding threat simulation and defense for Copilots and Agents

ToolsSecurity Research
Over Permissions in Salesforce Einstein and Unexpected Consequences

Over Permissions in Salesforce Einstein and Unexpected Consequences

Security Research
Outsmarting Copilot: Creating Hyperlinks in Copilot 365

Outsmarting Copilot: Creating Hyperlinks in Copilot 365

Security Research
The Long and Winding Road of DLP Patches in Power Platform

The Long and Winding Road of DLP Patches in Power Platform

Reviewing Microsoft's Fix for the 'All You Need Is Guest' DLP Bypass

Security Research
A Summary of Zenity Research Published at BlackHat 2024

A Summary of Zenity Research Published at BlackHat 2024

New Attack Vectors Discovered for Initial Access and Post-Compromise

TalksToolsSecurity Research
Copilot Vulnerable to RCE: A New Attack Vector Into The Enterprise

Copilot Vulnerable to RCE: A New Attack Vector Into The Enterprise

We Need To Address Promptware Now

TalksSecurity Research
Phantom References in Microsoft Copilot

Phantom References in Microsoft Copilot

Security Research
Links and materials for Living off Microsoft Copilot

Links and materials for Living off Microsoft Copilot

Links, source code, tools and slides for BlackHat USA 2024

ToolsTalksSecurity Research
Indirect Prompt Injection: Advanced Manipulation Techniques

Indirect Prompt Injection: Advanced Manipulation Techniques

Security Research
Links and materials for 15 Ways to Break Your Copilot

Links and materials for 15 Ways to Break Your Copilot

Links, source code, tools and slides for BlackHat USA 2024

ToolsTalksSecurity Research
Research Drop for Hacker Summer Camp 2024

Research Drop for Hacker Summer Camp 2024

More information on hacking Microsoft Copilot, Copilot Studio, powerpwn, and what to do next

ToolsTalksSecurity Research

Zenity Security Assessment Hub

10 free, open-source tools to help security teams to identify and understand immediate risks

Assess Your Risk